Audit Trail
The Audit Trail panel shows a chronological log of every governance event produced by TealTiger. Every request evaluated, every decision made, every cost recorded — all in one searchable timeline.Overview
The Audit Trail renders governance events in reverse chronological order (newest first):- Timestamp: Precise to milliseconds
- Action: ALLOW (green), DENY (red), SANITIZE (orange), REPORT (amber)
- Agent ID: Which agent produced the event
- Reason Codes: Why the decision was made (empty for ALLOW)
- Model: Which model was used
- Cost: Request cost
Filters
Event Type
Filter by governance action:Agent ID
Text input supporting partial match:- Type
researchto see all agents with “research” in their ID - Type a full agent ID for exact match
Text Search
Full-text search across event fields:- Searches: agent ID, reason codes, model name, correlation ID
- Case-insensitive
- Supports partial matches
Time Range
Pre-set time windows:- Last 1 hour
- Last 6 hours
- Last 24 hours
- Last 7 days
- Custom range (date picker)
Phase
Filter by governance direction:- Pre-execution events only
- Post-execution events only
- Both (default)
Expandable Event Details
Clicking any event row expands to show the full event payload:Expanded View Actions
Navigate to Evidence
Clicking the View Evidence button (or the “Inspect” icon) on any event navigates directly to:Event Types
The audit trail captures multiple event types:Pagination
The audit trail uses virtual scrolling for performance:- Loads 50 events at a time
- Infinite scroll loads more as you scroll down
- Total event count shown at top: “Showing 50 of 12,345 events”
- Filters update the count in real-time
Real-Time Updates
New events stream in via WebSocket:- A “New events” banner appears at the top when new events arrive while scrolling
- Click the banner to jump to the top and see the latest events
- Auto-scroll mode (optional): automatically scrolls to show new events as they arrive
Export
Export Filtered Results
When filters are active, an “Export” button downloads the filtered results as JSON:- Maximum 10,000 events per export
- Filename:
audit-trail-{timestamp}.json - Includes all event fields (not just the summary columns)
Performance
The audit trail is designed for high-volume environments:- Virtual scrolling (react-window) — only renders visible rows
- Server-side filtering — filters are applied at the API level, not in the browser
- Indexed queries — reason codes, agent ID, timestamp are indexed for fast lookups
- WebSocket for new events — no polling

